Worry Does Not Translate Into the Ability to Act

Organizations fear being cut off, but can't move critical workloads quickly — and nothing has made a dent. Most organizations are worried about a provider cutting them off, and only 24% could move quickly if one did. As governments place greater strategic weight on control of critical technologies, dependence on providers governed by a single jurisdiction is becoming a more material operational risk. The US decision in June 2026 to suspend access to a leading US AI provider's most capable models turned that scenario into a precedent. Yet, even organizations with mature sovereignty programs say that they cannot act quickly if they were cut off.

Respondents that are at least moderately concerned about a supply-chain kill switch: 87%

The risks buyers fear most are the ones that trap them

87% of organizations are at least moderately concerned about a supply-chain kill switch (a vendor or government shutting off hardware or software they depend on), and 81% about depending on US-headquartered providers for critical workloads. Asked which risks concern them most, buyers put vendor lock-in and exit difficulty first; foreign government access to data, the risk sovereignty usually brings to mind, comes fifth. What buyers want is the ability to leave, a procurement and architecture problem more than a data-residency one.

Sovereignty risks organizations name as their greatest concern All respondents (respondents could select more than one)

CategoryAll respondents
Vendor lock-in or exit difficulty32%
Regulatory fines, sanctions, or embargo30%
Foreign government access to data27%
Supply-chain disruption or hardware embargo27%
Sudden loss of a key vendor27%
Unsupported open-source vulnerabilities24%

Source: n=1,940 respondents, normalized by region

The ability for [a country or vendor] to actually… to invoke a kill switch and lock us out of our data is very real. — CDIO, public-sector (EMEA)

Only 2.9% of organizations hold all four capabilities needed to act

Four capabilities let an organization respond if a supplier cuts it off: a formal, documented, and tested contingency plan for vendor disruption; a plan for open-source software that can no longer be supported; a sovereignty risk framework applied to every supplier; and the ability to move a critical workload off a single cloud provider within 30 days.

Each capability is incomplete on its own. A contingency plan does not ensure workload portability. Portable workloads do not resolve an unsupported software dependency. A supplier-risk framework does not help if the organization cannot execute an exit. Taken together, the four provide a practical minimum test of whether a sovereignty program can operate under disruption. Only 2.9% of organizations meet that test. At the other end, 24.6% have none of the four capabilities. The gap is not simply one of policy maturity; it is a gap in operational readiness.

For leaders, the self-assessment is straightforward. Organizations that hold three of the four capabilities have identified part of the problem but still have a critical exposure. Those that hold one or none should begin with a full inventory of critical workloads, cloud providers, software dependencies, support arrangements, administrative access, and contractual exit rights. The objective is not to document every risk. It is to establish the minimum conditions for keeping critical services running when a dependency fails.

Only one organization in 35 holds all four capabilities sovereignty requires All respondents

CategoryAll respondents
Formal, documented, and tested contingency plan for a critical vendor being cut off41%
Formal plan for open-source software that loses its support40%
Risk framework applied to every supplier, not only the critical ones32%
Could move a critical workload off one cloud provider within 30 days24%

Source: n=1,940 respondents, normalized by region

Organizations that have all four of the essential operational sovereignty capabilities: 2.9%

Organizations that have none of the four essential operational sovereignty capabilities: 24.6%

Neither worry nor a mature program produces the ability to leave

Worry does not predict capability. A tested contingency plan is barely more common among organizations extremely concerned about a kill switch than among organizations not concerned, and even they are no more able to move a workload within 30 days. Program maturity shows the same pattern: organizations with sovereignty embedded in operations hold a tested plan far more often than organizations that have not put sovereignty on the agenda, yet the two groups' ability to move a workload within 30 days barely differs. Worry and maturity both buy governance, not readiness: a program's plans improve well before its ability to exit does.

Worry and maturity buy plans, not exits All respondents

CategoryHas a tested contingency plan
Not concerned41%
Moderately concerned39%
Extremely concerned45%
All respondents41%

Source: n=258 / 805 / 877 / 1,940 respondents

Worry and maturity buy plans, not exits: portability and risk framework, extremely concerned vs. everyone else All respondents

CategoryCould move a critical workload in 30 daysApplies a risk framework to every supplier
Extremely concerned about US dependence24%34%
Everyone else28%27%
All respondents24%32%

Source: n=734 / 1,206 / 1,940 respondents

Worry and maturity buy plans, not exits: tested plan and 30-day portability by sovereignty maturity All respondents

CategoryFormal, tested contingency planCould move a workload within 30 days
Not on our agenda40%23%
Exploring31%31%
Planning27%26%
Piloting46%23%
Deploying53%26%
Deployed & Embedded63%29%
All respondents41%24%

Source: n=90 / 334 / 504 / 396 / 343 / 273 / 1,940 respondents

We do not have a tested Plan B if a key vendor's hosting fails. Migrating from [a US hyperscaler] to [another US hyperscaler] remains a future ambition. — CDIO, Healthcare (EMEA)

Many factors drive provider-switching speed: size, industry, and region

Moving a critical workload off a single cloud provider takes most organizations months rather than weeks — 21 weeks on average — and the ability to do it within 30 days falls as organizations get larger, long enough that a disruption reaches far beyond the IT department. The largest enterprises are also the most likely to call sovereignty a critical priority, and the reasons they move slowest compound: more systems and legacy, slower change, multiple jurisdictions, and a larger, more visible target. As a result, the organizations with the most at stake are also the ones least able to respond quickly.

21 weeks · the average time to move a critical workload off a single cloud provider.

The organization's maturity in its sovereignty rollout has surprisingly little impact, with embedded-sovereignty organizations actually performing the slowest of any cohort in the sample. This doesn't indicate the sovereignty work slowed them; it likely reflects that these organizations had particularly strong need for such programs and still have many blockers, but the result is surprising nonetheless.

Other factors also make a difference. Asia-Pacific organizations are able to migrate much faster: a median of 10 weeks, versus 17 in North America, 18 in EMEA, and 19 in Latin America. Public sector organizations are uniquely slow: 17 weeks, versus 11 in financial services; 10 in healthcare and life sciences; 11 in telecom and digital infrastructure; 12 in manufacturing, industrial, and energy; and 13 in retail, consumer, and transportation.

Moving a critical workload takes about five months, and the largest organizations take longest All respondents · mean 144 days

CategoryAll respondents
Within 30 days24%
1–3 months26%
4–6 months28%
More than 6 months23%

Source: n=1,940 respondents, normalized by region

Moving a critical workload takes about five months, and the largest organizations take longest: portability within 30 days, by company size All respondents

CategoryCould move a workload within 30 days
500–99926%
1,000–4,99941%
5,000–9,99932%
10,000–24,99919%
25,000–49,99911%
50,000–99,99916%
100,000+22%
All respondents24%

Source: n=133 / 465 / 415 / 392 / 278 / 154 / 103 / 1,940 respondents

Organizations that could move a critical workload off one cloud within 30 days: 24%

Facing significant barriers, organizations procrastinate on sovereignty — waiting until external shocks force workload moves

Every leading event that would trigger moving workloads off a cloud provider is an external shock: new or stricter regulation, a security or compliance incident, a geopolitical event, and a vendor kill switch. Organizations are waiting for something to go wrong instead of building the capability in advance.

What Would Trigger Moving Off a US Hyperscaler All respondents (respondents could select more than one)

CategoryAll respondents
New or stricter regulation36%
Security or compliance incident34%
Geopolitical event, sanctions, or trade restrictions33%
Vendor "kill switch"31%
Government funding incentives28%
Customer or contractual requirement28%
Price increases / cost pressure28%
Board or executive directive27%
Nothing would trigger migration1%

Source: n=1,940 respondents, normalized by region

Barriers to sovereignty programs are primarily internal (in order): cost, technical complexity, legacy systems, a missing cloud and vendor inventory, and a skills gap. For organizations without sovereignty on their agenda, cost and budget is the runaway driver, named by 40% of these organizations, versus 29% overall. Small-to-midsize businesses and nonprofits identify both cost and technical complexity as major barriers than enterprises at notably higher rates; while those barriers still top the list for enterprises, they do report more significant barriers with legacy systems and technical debt, lack of inventory, and talent and skill gaps at higher rates.

The biggest barriers to sovereignty are inside organizations All respondents (respondents could select more than one)

CategoryAll respondents
Cost / budget29%
Technical complexity28%
Legacy systems / tech debt25%
Lack of cloud & vendor inventory21%
Unclear or shifting regulations20%
Talent & skills gap19%
Lack of mature vendor offerings17%
Internal disagreement on priorities15%

Source: n=1,940 respondents, normalized by region

Though buyers may fear a government cutting them off, the disruptions practitioners actually described were commercial: a vendor acquired and then shut down, an open-source component whose new owner began charging for it, cost changes buried in a contract. Price pressure ranks alongside geopolitical events among the triggers.

A vendor we used was acquired, then shut down with 2 years' notice. The real risk was migrating data we're required by regulation to retain for 9 years. — CTO, financial services (Asia-Pacific)
My main problem is I don't have enough people on my team, and there's no appetite to let me hire. I'm dependent on third parties, and that worries me. — CIO/CISO, electricity distribution company (Asia-Pacific)